Fireship · 2026-09-30 · notable
Fireship — 'Did a 50 year old military secret just solve agent prompt injection?'
Fireship's 30 September 2026 video looks at OpenAPPA, an open-source project that claims to fix rogue AI agents by checking every tool call against a data-flow policy before it runs.

Fireship explains OpenAPPA, an open-source guardrail that blocks agents from sending data where it should not go.
What is it?
'Did a 50 year old military secret just solve agent prompt injection?' is a Fireship video uploaded on 30 September 2026. It covers OpenAPPA from archestra-ai, a new open-source project that claims to have fixed the rogue agent problem.
How does it work?
OpenAPPA sits between an agent and its tools. Before each tool call it asks whether this data is allowed to go to this destination, tracking how sensitive the data is and how far each source can be trusted. Its decisions are deterministic: the same event log always gives the same result, with no network or file access needed.
Why does it matter?
Prompt injection is still the main way attackers turn coding and browser agents against their users. A policy check that does not rely on another model judging the request offers a guardrail that cannot be talked out of its rules.
Who is it for?
developers running AI agents with tool access